doc-validator
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process a corpus of user-provided markdown documentation files (BRD, PRD, BDD, etc.) for validation purposes. This creates a surface for indirect prompt injection where instructions embedded in the analyzed documents could attempt to influence the agent's behavior.
- Ingestion points: Project documents, section files, and adaptation profiles (
.aidoc/profile.yaml) located at the user-specifieddocs_path. - Boundary markers: The skill instructions do not specify the use of clear delimiters or guardrails to differentiate between document data and agent instructions during the validation process.
- Capability inventory: The skill performs file system read operations for all layers of the documentation and has file system write capabilities when
auto_fixis enabled to repair links or metadata. - Sanitization: While the skill normalizes terminology and ID formats, it does not implement specific sanitization to strip potential prompt injection sequences from the documentation content.
- [SAFE]: The skill operates entirely on local files within the project environment. It does not perform network operations, execute remote code, or request elevated privileges. All behaviors are consistent with its stated purpose as a quality assurance and utility tool.
Audit Metadata